27
The HTTP_REFERER check adds a layer of security. It makes it harder for someone to hack your site.
But the added security isn't very difficult to bypass.
Personally, I like having multiple layers of security, and prefer to have the HTTP_REFERER check. But I think it would be desirable to have a webmaster option for turning it off.
----
edit
The HTTP_REFERER can also be used to provide functionality, since it indicates the page the user came from, and some features might make use of that. I don't think this applies to Xoops, though.